mediumMultiple ChoiceObjective-mapped
MS-102 Practice Question: A company uses Azure AD Privileged Identity…
A company uses Azure AD Privileged Identity Management (PIM) to manage role activations. They have an Azure AD Premium P2 license. The security team wants to require that any activation of the Exchange Administrator role must be approved by a specific group named 'Exchange Approvers'. Additionally, activations must require a ticket number and expire after 6 hours. Which PIM configuration should the administrator modify?
⚠ Common exam trap
Candidates often confuse 'eligible assignments' (who can activate a role) with 'approvers' (who must approve activations), leading candidates to incorrectly select Option B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the 'Role settings' for the Exchange Administrator role to require approval and set the approvers group
In Azure AD PIM, the 'Role settings' for a specific role (like Exchange Administrator) allow you to configure activation requirements, including requiring approval, specifying approvers (such as the 'Exchange Approvers' group), requiring a ticket number, and setting a maximum activation duration (e.g., 6 hours). This directly meets all the security team's requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the 'Role settings' for the Exchange Administrator role to require approval and set the approvers group
Why this is correct
In Azure AD PIM, role settings for the Exchange Administrator role live under 'Role settings' in PIM. Editing this configuration lets you toggle 'Require approval to activate' and specify one or more approver groups or users; you can also enforce justification and ticket-number fields. Setting the Exchange Approvers group as the approver group ensures that every activation request is first reviewed by the designated approvers before the role becomes active. This is the only option that actually enforces an approval gate at activation time.
- ✗
Add the Exchange Administrator role to the 'Exchange Approvers' group's eligible assignments
Why it's wrong here
Adding the Exchange Administrator role to the 'Exchange Approvers' group's eligible assignments would make members of that group eligible to activate the Exchange Administrator role themselves, not to act as approvers for other users' activations. Approvers are selected in the role's 'Role settings' page, not through eligible assignments. In fact, this action would broaden access by giving the Exchange Approvers group the ability to self-request the privileged role, which is the opposite of what the company wants.
- ✗
Create a PIM alert for activations without a ticket number and set a 6-hour alert threshold
Why it's wrong here
PIM alerts are reactive detection mechanisms that generate notifications for suspicious activities—like repeated role activations or roles assigned outside PIM—but they do not enforce activation requirements. Configuring an alert for activations without a ticket number would only flag such events after the fact; it would not require approval or block the activation. A 6-hour threshold is an alert scheduling/tuning parameter, not an activation policy, so it has no bearing on whether approval is required.
- ✗
Define an access review for the Exchange Administrator role with a 6-hour review duration
Why it's wrong here
Azure AD access reviews are designed for periodic attestation of who still needs access—reviewers can approve or remove existing eligible/active assignments on a schedule, such as weekly or quarterly. Defining a review for the Exchange Administrator role would not affect the activation process itself; it would only check the continued validity of assignments after they have been granted. A six-hour review duration is also inconsistent with how access reviews work, because they are not timed per activation but run as recurring self-contained reviews, making this ineffective for enforcing approvals.
Go deeper
Related to this question
Learn chapter
Exchange Online Administration
Key term
Privileged Identity Management
Privileged Identity Management is a security system that controls, monitors, and audits access to sensitive systems by granting elevated permissions only when needed and for a limited time.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.